File name:

MouseServer.exe

Full analysis: https://app.any.run/tasks/230fdfa3-62ca-4df6-95c3-3c697d70e3e4
Verdict: Malicious activity
Analysis date: March 06, 2024, 07:52:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F55F4358135B428BA954ADBB55D32A57

SHA1:

B2BCEF855CDEE818941974CFD52737B73C24DBA6

SHA256:

6CE361B0A7BF6FD1DCE9E3D71674DA3D3A64C401ED94722E6EA4D3F98F4EA7C0

SSDEEP:

98304:h3F5+HCnCPrhxdHLUdT3UMSIm4yT1Jj38YtCxTuQbmQoxfJS+2KAv79ckiUjK/Vg:tPB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MouseServer.exe (PID: 1776)
      • MouseServer.tmp (PID: 2964)
      • net_updater32.exe (PID: 3428)
      • MouseServer.exe (PID: 1888)
      • Mouse Server Luminati.exe (PID: 568)
    • Create files in the Startup directory

      • MouseServer.tmp (PID: 2964)
    • Changes the autorun value in the registry

      • MouseServer.exe (PID: 1888)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MouseServer.exe (PID: 1776)
      • MouseServer.tmp (PID: 2964)
      • net_updater32.exe (PID: 3428)
      • MouseServer.exe (PID: 1888)
      • Mouse Server Luminati.exe (PID: 568)
    • Application launched itself

      • net_updater32.exe (PID: 1040)
    • Reads the Windows owner or organization settings

      • MouseServer.tmp (PID: 2964)
    • Checks Windows Trust Settings

      • net_updater32.exe (PID: 3428)
    • Reads security settings of Internet Explorer

      • net_updater32.exe (PID: 3428)
    • Reads settings of System Certificates

      • net_updater32.exe (PID: 3428)
      • Mouse Server Luminati.exe (PID: 568)
    • Process drops legitimate windows executable

      • net_updater32.exe (PID: 3428)
    • The process drops C-runtime libraries

      • net_updater32.exe (PID: 3428)
    • Reads the Internet Settings

      • net_updater32.exe (PID: 3428)
      • MouseServer.tmp (PID: 2964)
      • MouseServer.exe (PID: 1888)
      • Mouse Server Luminati.exe (PID: 568)
    • Detected use of alternative data streams (AltDS)

      • net_updater32.exe (PID: 3428)
      • Mouse Server Luminati.exe (PID: 568)
      • MouseServer.exe (PID: 1888)
    • Adds/modifies Windows certificates

      • net_updater32.exe (PID: 3428)
  • INFO

    • Reads the computer name

      • wmpnscfg.exe (PID: 3464)
      • MouseServer.tmp (PID: 2964)
      • net_updater32.exe (PID: 3428)
      • test_wpf.exe (PID: 3308)
      • MouseServer.exe (PID: 1888)
      • test_wpf.exe (PID: 2112)
      • Mouse Server Luminati.exe (PID: 568)
    • Checks supported languages

      • MouseServer.tmp (PID: 2964)
      • MouseServer.exe (PID: 1776)
      • wmpnscfg.exe (PID: 3464)
      • net_updater32.exe (PID: 1040)
      • net_updater32.exe (PID: 3428)
      • MouseServer.exe (PID: 1888)
      • test_wpf.exe (PID: 3308)
      • Mouse Server Luminati.exe (PID: 568)
      • test_wpf.exe (PID: 2112)
    • Create files in a temporary directory

      • MouseServer.exe (PID: 1776)
      • net_updater32.exe (PID: 3428)
    • Creates a software uninstall entry

      • MouseServer.tmp (PID: 2964)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3464)
      • msedge.exe (PID: 3680)
    • Creates files in the program directory

      • net_updater32.exe (PID: 3428)
      • MouseServer.tmp (PID: 2964)
      • net_updater32.exe (PID: 1040)
      • MouseServer.exe (PID: 1888)
      • Mouse Server Luminati.exe (PID: 568)
    • Reads the machine GUID from the registry

      • net_updater32.exe (PID: 3428)
      • MouseServer.exe (PID: 1888)
      • test_wpf.exe (PID: 3308)
      • Mouse Server Luminati.exe (PID: 568)
      • test_wpf.exe (PID: 2112)
    • Reads the software policy settings

      • net_updater32.exe (PID: 3428)
      • Mouse Server Luminati.exe (PID: 568)
    • Reads Environment values

      • net_updater32.exe (PID: 3428)
      • Mouse Server Luminati.exe (PID: 568)
      • MouseServer.exe (PID: 1888)
    • Process checks computer location settings

      • net_updater32.exe (PID: 3428)
      • Mouse Server Luminati.exe (PID: 568)
      • MouseServer.exe (PID: 1888)
    • Creates files or folders in the user directory

      • net_updater32.exe (PID: 3428)
      • MouseServer.exe (PID: 1888)
    • Checks proxy server information

      • net_updater32.exe (PID: 3428)
    • Application launched itself

      • msedge.exe (PID: 3680)
      • msedge.exe (PID: 2156)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (81.5)
.exe | Win32 Executable Delphi generic (10.5)
.exe | Win32 Executable (generic) (3.3)
.exe | Win16/32 Executable Delphi generic (1.5)
.exe | Generic Win/DOS Executable (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41472
InitializedDataSize: 71168
UninitializedDataSize: -
EntryPoint: 0xaa98
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.8.2.5
ProductVersionNumber: 1.8.2.5
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: 深圳市油桃科技有限公司
FileDescription: MouseServer.exe Setup
FileVersion: 1.8.2.5
LegalCopyright: Copyright © 2021-2022 深圳市油桃科技有限公司
ProductName: MouseServer.exe
ProductVersion: 1.8.2.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
30
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mouseserver.exe mouseserver.tmp wmpnscfg.exe no specs net_updater32.exe no specs net_updater32.exe msedge.exe no specs mouseserver.exe msedge.exe no specs test_wpf.exe no specs msedge.exe no specs msedge.exe no specs mouse server luminati.exe msedge.exe test_wpf.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs mouseserver.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
568"Mouse Server Luminati.exe"C:\Program Files\MouseServer.exe\Mouse Server Luminati.exe
MouseServer.exe
User:
admin
Company:
深圳市油桃科技有限公司
Integrity Level:
HIGH
Description:
Mouse Server Luminati.exe
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\program files\mouseserver.exe\mouse server luminati.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
992"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1452 --field-trial-handle=1384,i,8635822150141927425,5471018072636467801,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1040"C:\Program Files\MouseServer.exe\net_updater32.exe" --install-ui win_wifimouse.necta.us --dlg-app-name "Mouse Server" --dlg-tos-link "http://wifimouse.necta.us/MouseServerPrivacy.htm" --dlg-logo-link "http://wifimouse.necta.us/mouseserver.png" --dlg-bg-color "#ffffffff" --dlg-btn-color "#ff323232" --dlg-txt-color "#ff000000" --dlg-not-peer-txt limited --dlg-pos screen --dlg-benefit-txt "WiFi Mouse landscape keyboard & game padC:\Program Files\MouseServer.exe\net_updater32.exeMouseServer.tmp
User:
admin
Company:
Bright Data Ltd.
Integrity Level:
HIGH
Description:
BrightData service allows free use of certain features in an app you installed
Exit code:
2
Version:
1.305.614
Modules
Images
c:\program files\mouseserver.exe\net_updater32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
1556"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1220 --field-trial-handle=1336,i,12531485395011300818,7326397744170345363,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1776"C:\Users\admin\AppData\Local\Temp\MouseServer.exe" C:\Users\admin\AppData\Local\Temp\MouseServer.exe
explorer.exe
User:
admin
Company:
深圳市油桃科技有限公司
Integrity Level:
HIGH
Description:
MouseServer.exe Setup
Exit code:
0
Version:
1.8.2.5
Modules
Images
c:\users\admin\appdata\local\temp\mouseserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1888"C:\Program Files\MouseServer.exe\MouseServer.exe"C:\Program Files\MouseServer.exe\MouseServer.exe
MouseServer.tmp
User:
admin
Company:
深圳市油桃科技有限公司
Integrity Level:
HIGH
Description:
MouseServer.exe
Exit code:
0
Version:
1.8.2.5
Modules
Images
c:\program files\mouseserver.exe\mouseserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2068"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2148 --field-trial-handle=1384,i,8635822150141927425,5471018072636467801,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2112C:\Program Files\MouseServer.exe\test_wpf.exeC:\Program Files\MouseServer.exe\test_wpf.exeMouse Server Luminati.exe
User:
admin
Company:
Bright Data Ltd.
Integrity Level:
HIGH
Description:
test_wpf
Exit code:
0
Version:
1.305.614
Modules
Images
c:\program files\mouseserver.exe\test_wpf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2156"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://wifimouse.necta.us/install/success.htmlC:\Program Files\Microsoft\Edge\Application\msedge.exeMouseServer.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2404"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1608 --field-trial-handle=1384,i,8635822150141927425,5471018072636467801,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
20 336
Read events
20 135
Write events
173
Delete events
28

Modification events

(PID) Process:(2964) MouseServer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
940B0000C053134C9B6FDA01
(PID) Process:(2964) MouseServer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
B71A3ED5DBA69BB7B21494B00667F70EBE5361791F9ED47016BB6C91171E7554
(PID) Process:(2964) MouseServer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2964) MouseServer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\MouseServer.exe\MouseServer.exe
(PID) Process:(2964) MouseServer.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
375A41FE44135ADD8CFEC54A06A399DBB0FDF92C3A56926EFDC35ED97066D185
(PID) Process:(2964) MouseServer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7AFAA880-BB05-4E38-9279-C53EECE1B7BE}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.9 (a)
(PID) Process:(2964) MouseServer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7AFAA880-BB05-4E38-9279-C53EECE1B7BE}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\MouseServer.exe
(PID) Process:(2964) MouseServer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7AFAA880-BB05-4E38-9279-C53EECE1B7BE}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\MouseServer.exe\
(PID) Process:(2964) MouseServer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7AFAA880-BB05-4E38-9279-C53EECE1B7BE}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(2964) MouseServer.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7AFAA880-BB05-4E38-9279-C53EECE1B7BE}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
17
Suspicious files
59
Text files
72
Unknown types
37

Dropped files

PID
Process
Filename
Type
2964MouseServer.tmpC:\Program Files\MouseServer.exe\is-M4J3L.tmpexecutable
MD5:52C7C8CF5D10D306D0411B05C9E05C4C
SHA256:84402A052CD97B4A00DB2A4D90DCF2F6290E66C1A3938491795873A217B8CF9B
2964MouseServer.tmpC:\Program Files\MouseServer.exe\MouseServer.exeexecutable
MD5:15BC951073B34180E791959BFD23935E
SHA256:F7A3284ACD6A6B0B901946BFE1476AA5F654D4ADA0F568D19939EF79EE376443
2964MouseServer.tmpC:\Program Files\MouseServer.exe\is-94F39.tmpexecutable
MD5:2EBFED79BBF5704145293351BDDC424B
SHA256:2DFACDF691719ABC60494C96D1216E47E91919D6A2A3538343249534878B3DE7
2964MouseServer.tmpC:\Program Files\MouseServer.exe\BluetoothAdapter.dllexecutable
MD5:2EBFED79BBF5704145293351BDDC424B
SHA256:2DFACDF691719ABC60494C96D1216E47E91919D6A2A3538343249534878B3DE7
2964MouseServer.tmpC:\Program Files\MouseServer.exe\is-VN427.tmpexecutable
MD5:15BC951073B34180E791959BFD23935E
SHA256:F7A3284ACD6A6B0B901946BFE1476AA5F654D4ADA0F568D19939EF79EE376443
2964MouseServer.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\MouseServer.exe.lnklnk
MD5:83E71424441F21E3D652EE2EA1B1FDAA
SHA256:E60026F232CD7FF96E4A810007E984722C33929E903592F5703055A2F3EC74BF
2964MouseServer.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\(Default)\MouseServer.exe.lnkbinary
MD5:D3729175C689CDF74493EBE025C591CF
SHA256:6C93FD4DE4AA73A38098680495E8974048231A663FCD7BA66FF93C0E94B650FD
2964MouseServer.tmpC:\Program Files\MouseServer.exe\is-3DG3L.tmpexecutable
MD5:A71CD0D7859F5D2402717D987A54C798
SHA256:8A25F2444C4D1B9F9BB96EFEC392A78412FFF5BA44D7B864E263509B7194064D
2964MouseServer.tmpC:\Program Files\MouseServer.exe\unins000.datdat
MD5:DF91B6DFCFF7F243A21F6885CCCEF0DE
SHA256:2706D65572F74609C5E0E5CFE0B8B17215C8A470DF25BF283F176FA673F6DA59
2964MouseServer.tmpC:\Users\Public\Desktop\MouseServer.exe.lnklnk
MD5:109487682EE4F25A6B8AF7BA93BAB4F6
SHA256:EF9A61C4A554A033B01886B4CE9D3BB579CD3D3BD57C99E5AAECE7FFED8198E0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
40
DNS requests
29
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3428
net_updater32.exe
GET
301
162.144.62.9:80
http://wifimouse.necta.us/mouseserver.png
unknown
html
250 b
unknown
992
msedge.exe
GET
301
162.144.62.9:80
http://wifimouse.necta.us/install/success.html
unknown
html
255 b
unknown
3428
net_updater32.exe
GET
200
23.223.209.21:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6578879dcf199db3
unknown
compressed
67.5 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
unknown
224.0.0.252:5355
unknown
3428
net_updater32.exe
192.81.214.145:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
unknown
3428
net_updater32.exe
3.228.36.186:443
clientsdk.lum-sdk.io
AMAZON-AES
US
unknown
3428
net_updater32.exe
162.144.62.9:80
wifimouse.necta.us
UNIFIEDLAYER-AS-1
US
unknown
3428
net_updater32.exe
162.144.62.9:443
wifimouse.necta.us
UNIFIEDLAYER-AS-1
US
unknown
3428
net_updater32.exe
23.223.209.21:80
ctldl.windowsupdate.com
Akamai International B.V.
US
unknown
1888
MouseServer.exe
192.168.100.255:2008
whitelisted
3680
msedge.exe
239.255.255.250:1900
unknown

DNS requests

Domain
IP
Reputation
perr.lum-sdk.io
  • 192.81.214.145
  • 159.223.133.120
  • 161.35.48.195
  • 206.189.231.23
unknown
perr.l-err.biz
  • 192.81.214.145
  • 161.35.48.195
  • 159.223.133.120
  • 206.189.231.23
unknown
clientsdk.lum-sdk.io
  • 3.228.36.186
  • 3.228.177.90
unknown
wifimouse.necta.us
  • 162.144.62.9
unknown
ctldl.windowsupdate.com
  • 23.223.209.21
  • 23.223.209.44
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
cdnjs.cloudflare.com
  • 104.17.24.14
  • 104.17.25.14
whitelisted
fonts.googleapis.com
  • 142.250.185.202
whitelisted
ajax.googleapis.com
  • 216.58.206.42
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .biz TLD
No debug info